vendor:
Seyon
by:
jkh
7.2
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Seyon
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD, Irix
1999
Seyon Relative Pathname Vulnerability
Seyon uses relative pathnames to spawn two other programs which it requires. It is possible to exploit this vulnerability to obtain the privileges which seyon runs with. It is installed (by default) setgid dialer on FreeBSD and root on Irix.
Mitigation:
Ensure that relative pathnames are not used to spawn programs.